A practical grounding in how a web application recognizes a returning authenticated user across multiple requests without re-verifying credentials every time. Covers session identifier generation and why insufficient randomness undermines the entire mechanism, session fixation as a specific attack pattern and the defense of regenerating the identifier at login, the three secure cookie attributes and what each one actually protects against, session timeout design, invalidation at required trigger points including the common client-only logout mistake, concurrent session handling, and session management across a distributed, multi-service architecture.
Nothing. Every course, exam, and certificate on the catalog is free — including retakes. All you need is a free Safeguard account.
None. The flagship course, Safeguard Certified Practitioner, is a beginner-level course — basic familiarity with how software is built helps, but every exam question is answerable from the lessons themselves.
You can retake it after a 24-hour cooldown, as many times as you need. Retakes are free, and each attempt draws a fresh random set of questions.
The Safeguard Certified Practitioner credential is valid for 24 months from issue. The expiry date is printed on the certificate and shown live on its public verification page. Renewing means passing the current exam again.